Global rank
#2
All-time leaderboard
Total points
11,700
Across CTF seasons
Challenges solved
5
Distinct arenas
Captures solved
26
2796h 55m total
Activity
Submission rhythm.
Monthly captures
Monthly Captures
Submissions
Public captures.
| Challenge | Objective | Status | Score |
|---|
| Challenge | Objective | Status | Score |
|---|---|---|---|
NexaCorp: Zero Credentials | You walk through a door using an identity you forged | Completed | 450 pts |
NexaCorp: Zero Credentials | The server fetches something internal on your behalf | Completed | 450 pts |
NexaCorp: Zero Credentials | You gave yourself access the system never intended to grant | Completed | 450 pts |
NexaCorp: Zero Credentials | A credential meant for someone else ends up in your hands | Completed | 450 pts |
NexaCorp: Zero Credentials | Something was left exposed that shouldn't be public | Completed | 450 pts |
VulnCorp | What is the flag from the secrets vault accessed by exploiting the fail-open authentication bypass? | Completed | 450 pts |
VulnCorp | What is the flag returned by the exfiltration callback endpoint of the backdoored supply chain package? | Completed | 450 pts |
VulnCorp | What is the flag extracted from the AI assistant's internal configuration through prompt injection? | Completed | 450 pts |
VulnCorp | What is the flag retrieved from the internal cloud metadata service accessed via Server-Side Request Forgery? | Completed | 450 pts |
VulnCorp | What is the flag received after verifying the admin credentials obtained through SQL injection and password hash cracking? | Completed | 450 pts |
VulnCorp | What is the flag obtained from the debug admin panel accessed through secrets leaked in the exposed git commit history? | Completed | 450 pts |
Droid-Warden | If you’ve made it through the last door, it’s time to search for the treasure hidden within. | Completed | 450 pts |
Droid-Warden | Broken authentication is an invitation to attackers to walk right in. You don’t need to break the front door, it’s already unlocked. | Completed | 450 pts |
Droid-Warden | Feeling unwell? A doctor uses an injection. Some systems react similarly when prodded the right way. | Completed | 450 pts |
Droid-Warden | User “daniel” seems innocent enough, but not everyone takes security seriously, and he’s no exception. | Completed | 450 pts |
Droid-Warden | Look beyond what the app shows you to uncover the first flag. | Completed | 450 pts |
TravelEndpoint | Data is only as secure as its weakest link. Can you uncover information that shouldn't be accessible? | Completed | 450 pts |
TravelEndpoint | A system's curiosity can sometimes lead it to unexpected places. Can you make it fetch something valuable? | Completed | 450 pts |
TravelEndpoint | Certain reports are meant for specific eyes only. Can you access what's not meant for you? | Completed | 450 pts |
TravelEndpoint | Sometimes, what you send isn't what's saved. Can you manipulate the system to reveal what's hidden? | Completed | 450 pts |